Home→Blog→What we detect→Email
|
14 Mar Reminder: be careful opening invoices on the 21st March Ben Godwood 08 Mar CIA "DELETED" Venezuela's Hugo Chavez? Dmitry Bestuzhev 10 Jul Is it the end of the DNSChanger Trojan? Dmitry Bestuzhev 16 May Carolina Dieckmann, Brazilian cybercrime legislation and la “Viveza criolla” Dmitry Bestuzhev 17 Jan Internal needs on the black market Dmitry Bestuzhev 05 Jan A few words about the HLux botnet Dmitry Bestuzhev Join our blog You can contribute to our blog if you have +100 points. Comment on articles and blogposts, and other users will rate your comments. You receive points for positive ratings. |
On March 4th we spotted a large number of unusual emails being blocked by our Linux Mail Security product. The emails all contained the same PDF attachment (MD5: 97b720519aefa00da58026f03d818251) but were being sent from many different source addresses.
The emails were written in German and most were sent from German IP addresses. Below is a map showing the distribution of addresses:

The computer names referenced in the mail headers were often of the form Andreas-PC or Kerstin-Laptop (the names have been changed to protect the innocent) suggesting that they had been sent from German home computers.
Analysis
Blog

Analysis
Blog

Analysis
Blog
Alerts
Analysis
Blog


Analysis
Blog
